Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

Google News
socprime.com > blog > logtotal-public-preview-free-private-security-log-analysis

LogTotal Public Preview: Private Log Analysis

4+ hour, 56+ min ago   (433+ words) Security teams don’t have a data shortage — they have a data flood. A single incident can throw off hundreds of thousands, sometimes millions, of log events, and making sense of them under time pressure is exactly the kind of work…...

SOC Prime
socprime.com > active-threats > uat-10147-uses-agentic-ai-to-expand-post-compromise-activity

UAT-10147 Uses Agentic AI for Post-Compromise Attacks

16+ hour, 39+ min ago   (268+ words) SOC Prime Bias: High UAT-10147 is a Chinese-speaking cybercrime group using agentic AI to automate and scale post-compromise operations. The actor targets Windows and Linux web servers for SEO fraud and data theft. Its AI-driven tooling supports exploit refinement, reconnaissance,…...

SOC Prime
socprime.com > active-threats > agent-tesla-bec-attack-delivers-an-in-memory-infostealer

Agent Tesla BEC Attack Delivers In-Memory Infostealer

16+ hour, 59+ min ago   (323+ words) SOC Prime Bias: High A Business Email Compromise (BEC) campaign is using a sophisticated JScript dropper to distribute Agent Tesla v4 malware. The attack relies on Unicode emoji obfuscation to evade signature-based detection and uses DonutLoader to execute a reflective payload…...

SOC Prime
socprime.com > active-threats > rust-supply-chain-attack-targets-arrayref-internment-and-append-only-vec

proc-macro1 Supply Chain Attack Hits Rust Crates

16+ hour, 46+ min ago   (115+ words) SOC Prime Bias: Critical Rationale: This section details the precise execution of the adversary technique (TTP) designed to trigger the detection rule. The commands and narrative MUST directly reflect the TTPs identified and aim to generate the exact telemetry expected…...

SOC Prime
socprime.com > active-threats > kimsuky-uses-legitimate-rmm-tools-in-northeast-asia-campaigns

Kimsuky Abuses Remote Access Tools Across Northeast Asia

17+ hour, 5+ min ago   (215+ words) SOC Prime Bias: Critical Users should exercise caution when opening LNK files or links received from unknown sources, especially because Windows can hide file extensions. Organizations should regularly audit installed software for unauthorized Chrome Remote Desktop or AnyDesk deployments. Monitoring…...

SOC Prime
socprime.com > active-threats > silkparasite-targets-central-asia-in-china-nexus-apt-campaigns

SilkParasite China-Nexus APT Targets Central Asia

5+ day, 7+ hour ago   (147+ words) SOC Prime Bias: High We are still updating this part. Rationale: This section details the precise execution of the adversary technique (TTP) designed to trigger the detection rule. The commands and narrative MUST directly reflect the TTPs identified and aim…...

SOC Prime
socprime.com > active-threats > def-con-themed-phishing-abuses-google-apps-script-for-malware-delivery

Post-DEF CON Phishing Abuses Google Apps Script

5+ day, 7+ hour ago   (169+ words) SOC Prime Bias: High Users should treat unexpected requests to execute terminal commands, bypass Gatekeeper, or install manual updates from document sidebars as suspicious. Organizations should monitor for unusual Google Apps Script activity and unauthorized use of code-signing certificates. Strong…...

SOC Prime
socprime.com > active-threats > malware-campaign-targets-korean-web-servers-running-softether-vpn

SoftEther VPN Malware Targets Korean Web Servers

6+ day, 16+ hour ago   (274+ words) SOC Prime Bias: High The Larva-26010 threat actor is targeting web and MS-SQL servers in South Korea to deploy SoftEther VPN. Compromised systems are repurposed as VPN servers, potentially using cascade connections to conceal the attackers’ true C&C infrastructure....

SOC Prime
socprime.com > active-threats > operation-asterix-anatomy-of-a-crypto-fraud-pipeline

Operation ASTERIX Exposes a Crypto Fraud Pipeline

6+ day, 16+ hour ago   (115+ words) SOC Prime Bias: High Rationale: This section details the precise execution of the adversary technique (TTP) designed to trigger the detection rule. The commands and narrative MUST directly reflect the TTPs identified and aim to generate the exact telemetry expected…...

SOC Prime
socprime.com > active-threats > fake-claude-search-results-lead-macos-users-to-macsync-stealer

Google Search for Claude Delivers MacSync Stealer

6+ day, 16+ hour ago   (166+ words) SOC Prime Bias: High Users should avoid copying and executing unverified commands in Terminal, even when instructions appear on legitimate or trusted domains. Security teams should monitor for suspicious curl activity and Base64-encoded content within shell processes. Tools such as…...